Investigation · Account & Purchase Data

Suno Data Breach Investigation

Hall Attorneys is evaluating potential claims for Suno users after a reported November 2025 security incident involving 55.3 million email addresses and tens of thousands of Stripe purchase records.

Reported scale
55.3M

unique email addresses

Incident date
November 2025

according to public reports

HIBP listing
July 20, 2026

dataset added to breach index

Answer at a glance

What happened in the Suno data breach?

Public reporting describes a November 2025 security incident in which an attacker obtained Suno source code and customer information. Have I Been Pwned later analyzed the reported dataset and listed 55.3 million unique email addresses.

TechCrunch reported that Suno confirmed the incident but had not publicly disclosed it on its website or provided the outlet with a copy of any notice sent to users as of July 21, 2026. The precise information associated with each person may differ.

This is an investigation, not a filed lawsuit. Facts may change as Suno, regulators, or security researchers publish additional information.

  1. Reported security incident

    A hacker later claimed that a supply-chain attack exposed an employee's credentials and enabled access to Suno systems. TechCrunch reported that Suno described the event as a limited security incident that was quickly contained.

  2. The incident becomes public

    404 Media reported on breached Suno source code, customer information, and Stripe payment data. TechCrunch reported the same day that Suno had not notified customers about the November incident.

  3. Have I Been Pwned quantifies the dataset

    Have I Been Pwned added the breach to its index and reported 55.3 million unique email addresses, plus phone numbers and tens of thousands of Stripe purchase records.

  4. Suno confirms an incident

    TechCrunch reported that a Suno spokesperson confirmed a November 2025 security incident and did not dispute the number of affected users. The outlet said Suno did not provide a copy of any user notification when asked.

Reported data categories

What information was exposed?

Most of the reported corpus consisted of email addresses. Other information was present only for some users or within a smaller set of Stripe purchase records.

Important distinction

Public sources do not list passwords or full card numbers as compromised data. Partial card details still create phishing and impersonation risks when combined with names, addresses, and purchase information.

Account identifiers
Email addresses and, for some accounts, phone numbers
Customer details
Names and physical addresses within reported Stripe records
Purchase information
Purchase amounts and related transaction records
Partial card data
Card type, expiration date, and last four digits—not full numbers

Who may want to contact us

Current and former Suno users

The investigation is focused on people whose Suno account, contact, address, purchase, or partial payment-card information may appear in the reported dataset, especially users experiencing misuse or related loss.

Current or former Suno users whose email address appears in the reported dataset

People who used a phone number to create or access a Suno account

Suno customers whose purchases were processed through Stripe

Users receiving targeted phishing, payment-themed messages, or suspicious account communications after the incident

What to preserve

Keep records before sending anything sensitive

Preserve the records below, but do not send passwords, authentication codes, complete card numbers, or unredacted financial records through ordinary website forms.

Suno account records

Save account-creation emails, profile screenshots, subscription information, and any security or privacy communications from Suno. Include dates where possible.

Purchase and billing records

Preserve Suno receipts, Stripe receipts, subscription changes, refund records, and card alerts. Redact full card numbers before sharing documents by ordinary email.

Suspicious messages

Keep phishing emails, texts, or direct messages that reference Suno, AI music, subscriptions, billing, refunds, account verification, or personal information.

Account-security alerts

Save password-reset messages, unfamiliar-login alerts, two-factor authentication prompts, and records of account changes you did not request.

Breach-check results

Keep a dated screenshot or PDF if a reputable breach-notification service reports that your email address appears in the Suno dataset.

Time, expenses, and harm

Track time spent securing accounts, replacing cards, monitoring transactions, responding to phishing, or addressing identity theft or financial loss.

Investigation focus

Issues under review

Hall Attorneys is reviewing the reported attack, the data involved, Suno's response and notice assessment, and follow-on harms reported by users.

  1. How many current and former Suno users in the United States and individual states were affected
  2. Which account, contact, address, purchase, and partial payment-card fields were associated with each person
  3. How the reported attacker obtained employee credentials and accessed customer and Stripe information
  4. When Suno learned of the incident and how it assessed the need to notify affected users or regulators
  5. Whether Suno's public description of a limited incident is consistent with the later-reported dataset
  6. Whether users experienced phishing, account misuse, payment-card problems, identity theft, financial loss, or time loss

Public reporting reviewed

Sources for the Suno incident

The factual statements above distinguish Suno's reported response from third-party dataset analysis and attacker claims. They may change as more information becomes available.

Have I Been Pwned ·

Suno Data Breach

Lists 55.3 million unique email addresses and the account, purchase, address, and partial payment-card data categories reportedly involved.

Read source: Suno Data Breach

Contact the firm

Was your Suno account included?

Contact Hall Attorneys with your name, contact information, general relationship to Suno, and a summary of any notice or suspicious activity. Do not include passwords, authentication codes, complete card numbers, or unredacted financial records in an initial message.

Contact Hall Attorneys

Common questions

Suno data breach FAQ

Is this a filed Suno lawsuit?

No. This page describes an investigation by Hall Attorneys. It does not state that Hall Attorneys has filed a lawsuit over the Suno incident.

Did Suno confirm a data breach?

TechCrunch reported on July 21, 2026 that a Suno spokesperson confirmed a November 2025 security incident and did not dispute the reported number of affected users. Have I Been Pwned separately lists the incident as the Suno data breach.

How many Suno users may be affected?

Have I Been Pwned lists 55.3 million unique email addresses. That figure describes unique addresses in the dataset; it should not be read as 55.3 million paying customers or as proof that every listed person had every data category exposed.

What information was reportedly exposed?

The reported categories include email addresses, phone numbers used for sign-up, and tens of thousands of Stripe records containing names, physical addresses, purchase amounts, card type, expiration date, and the last four digits of a card. The information associated with a particular person may vary.

Were Suno passwords exposed?

Have I Been Pwned does not list passwords among the compromised data categories for this incident. Users should still use a unique password, change any reused password, and enable two-factor authentication where available.

Were full credit card numbers exposed?

The public reports describe partial card data—not full card numbers—including card type, expiration date, and the last four digits. Have I Been Pwned reports that Suno said it does not have access to customers' full credit card numbers in Stripe.

Did Suno notify affected users?

TechCrunch reported that Suno had not notified customers about the November 2025 incident and, as of July 21, did not provide the outlet with a copy of any user communication when asked. Whether any person received a separate notice remains an issue under investigation.

What should I do after the Suno breach?

Use a unique password, enable two-factor authentication where available, monitor the payment card used with Suno, watch for targeted phishing, access Suno through a known official address, and preserve relevant account, purchase, and security records.

Attorney Advertising

Hall Attorneys is not affiliated with Suno, Stripe, or Have I Been Pwned. This page concerns an investigation, not a filed lawsuit. Sending information does not create an attorney-client relationship. Do not send passwords, authentication codes, complete card numbers, government identification, or other highly confidential information unless specifically requested through a secure channel.